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DIRECTOR OF CENTRAL INTELLIGENCE 
Security Committee 


SECOM-D-324 


18 August 1980 


MEMORANDUM FOR: Chairman, SECOM 


FROM: 
ES/SECOM 


SUBJECT: Storage of APEX Nondisclosure Agreement 


1. The issue of CIA providing a central repository for 
storage of the Nondisclosure Agreement has arisen again. 


2. The Department of State has acquiesced and it looks 
like there will be a standard APEX NdA. 


3. [.___]is the CIA representative to one of 
APEX Working Groups chaired by 
of the AF (also the AF SECOM member). At a recent meeting 
everyone except NSA and CIA opted for CIA to provide the 
repository. = wanes a statement of position. 


4. I've repeatedly informed[_|that OS would 
not be equipped to do this with current resources. But I 
havent't told him how many resources it would take to make 
OS change its mind. 

5. As close as I can figure, we are talking about 
holding up to 200,000 NdA within the first two years of APEX 
and adding to this at the rate of probably 5-10,000 per month 


(on the high side), 3-5,000 per month on the low side. Original 


paper would have to be stored for 70 years. While there may 
not be active interplay of this material, there would be 

a need for an organized file subject to access and document 
retrieval on reasonable notice. 
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6. Resource requirement for this task are computed to 
he 2 people at the clerk level (GS-5 or GS-6) for the first 
year and one GS-6 full time each year thereafter. Space 
requirements would be approximately 40 linear feet the first 


year and an additional 2 or 3 linear per 
Before the first copy could be destroyed 
initiation date), the holdings will have 
more than 300 linear feet of space. The 
unclassified but will require protective 
weather hazards and effects of time. 


year thereafter. 
(70 years from 
grown to require 
material is 
storage against 


7. C........_] continues to support the idea of 
central storage by CIA and I'm sure he will again seek your 
support and agreement to provide this service of common 


concern. 


Shall we encourage? 


or 
Shall we discourage? 


Distribution: 
Orig Return ES/SECOM 
L - C/SECOM 
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15 August 1980 


MEMORANDUM FOR: Deputy Director of Security/CA 


FROM: SS 
- Chief, Special Security Center 


SUBJECT: APEX Nondisclosure Agreements | 


Le The attached agenda for the 14 August 1980 Working 
Group One meeting contains an item on the Nondisclosure 
Agreement which generated substantial discussion and disagree- 
ment. Most of the agencies represented were strongly in 
favor of a central repository for all Nondisclosure Agreements “- 
opposed to burdening the individual SIO's with this responsi- © 
bility for which they have no resources. 


ay [_....... ] polled the attendees and found that all 
favored a central repository except NSA (which preferred to 
maintain its own Nondisclosure Agreements) and CIA, which 
abstained. would appreciate a CIA position on a 
central repository for Nondisclosure Agreements--the point 
being that all other agencies (except NSA) would like to see 
CIA accept this responsibility to which I could not commit 
either OS or CIA. 

a I would appreciate guidance on this matter--even in 
the form of a memo from[__ ~~ ~~~*+4S -putting the Office on 
record as either accepting or declining to assume the role of 
Nondisclosure Agreement keeper for the community, and the 
concomitant resource impact such an acceptance would entail. 
The recent decision by National Archives that the Nondisclosure 
Agreement might have to be maintained for some seventy (70) 
years should also be considered. 


25X1A 
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INSC 


APEX Nondisclosure Agreements (NDAs) 


Chairman, APEX Steering Group 
Room 7E12, CIA HQ Building 


l. During the 29 July 1980 meeting of the APEX Steering Group 

you tasked Working Group No 1 with preparing a draft letter to the 
NFIB SIOs on establishing repositories for the APEX Nondisclosure 
Agreements (NDAs) in their respective departments and agencies and 
specifying other related details. 


2. A draft of such a letter is attached for your consideration. 


1 Atch 
Chairman, APEX Working Group Draft ltr on APEX NDAs 
Number 1 
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DRAFT 
MEMORANDUM FOR NATIONAL FOREIGN INTELLIGENCE BOARD 
SUBJECT: APEX Nondisclosure Agreements (NDAs} 


1. Subsequent to a newd~to-know certification and favorable 
DCI 1/14 adjudication, all persons must undergo a security in- 
doce. nation and execute a Nondisclosure Agreement (NDA) as a 
condition of access to APEX material. Subsequent access to 
compartments within the APEX system will be accompanied by 
security indoctrinations that will include a reminder of the 
original NDA and its obiigation. 


2. The NDAs will be distributed to the Intelligence Community 
in the near future together with instructions explaining its 
legal implications. Implementation of the APEX orientation pro- 
cess will then commence. 


3. As the NDA basically constitutes a legal document reflecting 
the signer's willingness to adhere to its provisions as a condi- 
tion of access to APEX information, its preservation is a matter 
of vital concern for possible prosecution and other purposes. 


We have been unable to obtain agreement on the concept of retaining 


the NDAs in a central repository. Accordingly, each NFIB SIO 
must establish policies and procedures for the retention of NDAs 
completed by persons under his/her APEX security cognizance. 


4. he attached guidelines are provided to insure that the In- 
telligence Community has a uniform policy on the retention of 
APEX NDAs. 


en 


Attachment 
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GUIDELINES FOR RETENTION AND HANDLING OF ‘HE 


‘APEX NONDISCLOSURE AGREEMEN'T (NDA) 


~ AND _ RELATED - ACTIONS 


1. NDA Repository. Intelligence Community SIOs are responsible to 
maintain a repository for all NDAs completed by persons authorized 
APEX access under their APEX security cognizance. The NDAs should 
pe kept for 70 years or whatever period is subsequently prescribed 
py proper legal authority. NDAs should be maintained in such a 
format (e. g., alphabetical by year) so as to be easily retrieved 
when required for legal or other purposes The original signed 
copy of the NDA must be retained in the repository unless it is 
subsequently determined by proper legal authority that microfiche, 
xerox, or other forms of the original NDA are sufficient for pros- 
ecution purposes. Copies of the original NDA may be prepared and 
used elsewhere when needed for management, record keeping, or 
other purposes. 


Ze Location of the Repository. The logical site for the repository. 
is in the Washington DC Metropolitan area~-preferably in areas 
controlled by the Intelligence Community SIO. This would facilitate 
interplay with the "current access status" and "access history” 
functions of the Community-wide, Computer-assisted, Compartmentation 


Control (4C) System to be established under APEX. 


au Handling of — NDAs: 


a. Initial APEX Indoctrination. The original signed NDA should 
be forwarded to the Intelligence Community. SIO who authorized APEX 
indoctrination. This SIO would be responsible for submitting re- 
quired data to the 4C system (or interim pre-4C system) and then 
retaining the NDA in its repository. IC SifOs may require a person 
to aperiodically complete additional NDAs for record-keeping, 
security, or other purposes. NDAs completed under these condi- 
tions need not be kept in the repesitory and may be destroyed 

when no longer needed. 


b. Recording Individual APEX Access Categories. Each time a 
person is authorized access to an individual APEX Conpabement 
supcompartment, product, or other APEX category, the fact will be 
reported to the SIO authorizing access who will enter the data in 
the 4C system. There is no need to record this access in the 


Intelligence Community SIO's NDA repository. 


c. Debriefings. When a person is debriefed in toto or is 
removed from one or more APEX accesses, the Debriefing Certificate 
(DC) must pe forwarded to the SIO who authorized the access. This 
SIO will enter the data into the 4C system and keep or destroy the 
DC, as desired. The DC need not be retained in the repository. 
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d. Transfers Among Intelligence Comaunity 810s. Whenever a 
person under the APEX security cognizance of one Intelligence 
Community SIO is assigned (i. ew, “in-status transfer, or change 
of employment) to duties requiring APEX access under the cogni- 
zance of another Intelligence Community Sf0, the person will be 
required to sign another NDA. this NDA will be retained and 
handled by the gaining Intelligence Community SIO as outlined in 
paragraphs 1 and 3a, above. This is to facilitate the processing 
of security reviews and other matters which might arise as the 
result of APEX access acquired as the result of duties with the 
gaining Intelligence Community SIO. 


e. APEX Access Subsequent to Debriefing. Whenever a person 
is debriefed in toto and is again subsequently authorized APEx 
access, another signed NDA must be accomplished and handled as 
outlined in paragraphs 1 and 3a, above. 


Approved For Release 2003/02/27 : CIA-RDP82M00591R000200050015-0 


Approved Forelease 2003/02/27 : CIA-RDP82M0059%%000200050015-0 


APEX STEERING GROUP 
WORKING GROUP NUMBER ONE 


8 August 1980 


AGENDA 
Meeting, Thursday, 14 August 1980, 1000 Hours 
Room BD-951, Pentagon 


ITEM 1 Preliminary Comments 


ITEM 2 APEX Nondisclosure Agreement (NDA). (Please review 
the attached draft letter and be prepared to concur 
or provide alternate wording.) 


ITEM 3 APEX Briefing Guide. (Please review the attached 
Graft letter and be prepared to concur or provide 
alternate wording.) 


ITEM 4 New business. 


25X1A 
2 Atchs 
Chairman, APRX Working Group 1. Draft ltr, APEX Non- 
Numper 1 disclosure Agreements (NDAs) 
w/Atch 


2. Draft ltr, APEX Briefing 
Guide w/Atch 


DISTRIBUTION: See reverse 
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INSC 


APEX Briefing Guide 


Chairman, APEX Steering Group 
Room 7E12, CIA HQ Building 


lL. You tasked Working Group No 1 with preparing a draft APEX 
Briefing Guide based on preliminary guides submitted by the SECOM 
(SECOM-D-246) and the DIA member of our group (my ltr, 14 Jul 80). 


2. A draft of such a guide is attached for your consideration. 

It is predominantly a "checklist" type guide as the group believes 
this style would be more helpful to field activities As noted in 
paragraph 2 of my.14 July 1980 letter on this matter, APEX Program 
Managers must supplement the attached guide with secondary briefings 
on the various APEX compartments, subcompartments, and product 
categories under their cognizance. 


5 | | 1 Atch | 
Chairman, APEX Working Group Draft APEX Briefing Guide 


Number 1 
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DRAFT? 


APEX BRIEFING GUIDE 


FOREWORD 


This guide is offered to assist personnel engaged in conduct- 
ing personnel security priefings on inatters within the purview of 
the APEX Special Access Control Syste. 


The guide has been prepared in “checklist” format so that brief- 
ing officers can extract from it, in part or in whole, elements that 
satisfy their unique requirements within full applicability of the 
need-to~know concept. 


There are certain core concepts which imust be incorporated in 
all briefings: 


a. The individual must be told what he is to protect. 


b. The individual must be told how he is expected to pro- 
tect the information and those procedures must be explained to him 
in understandable terms to his acknowledged satisfaction. 


c. The individual must sign a Nondisclosure Agreement (NDA) 
and have explained to his satisfaction what the conditions of that 
agreement are. 


No predetermined word pattern can be offered to satisfy all 
perceptions of needs in briefing personnel who are expected to 
protect material using the APEX Special Access Control System. 
But the core concepts must be incorporated into the briefing. 


The guide does not include specifics of the various APEX opera- 
tional compartments, subcompartments, product compartments. Briefers 
must obtain this information from manuals and information dissemina- 
ted by the APEX Program Managers and provide it on a need-to-know 
basis to the individual being briefed. 


It is recognized that persons who have been indoctrinated into 
former compartmented intelligence programs will only require a mini- 
mum briefing to permit conversion to the APEX system. The briefing 
officer should adjust his briefing accordingly. 
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It is further recognized that there exist a number of 
personnel currently on the periphery of the APEX system who 
historically have been incorporated under an umbrella concept 
of program compartmentation. The required tests for determina- 
tion of what material may be afforded peotection of the APEA 
Special Access Control System may result in a determination 
that some activities, and thus some personnel, are outside of 
APEX compartmentation. The inclusion of material or activity, 
and thus personnel associated with this material or activity 
under APEX protection, does not mandate revelation of more in- 
formation in the security briefing than is essential to do the 
joo and help the individual recognize what it is he/she is to 
protect and how he/she is to accomplish this protection. 


General Officers and other "VIPs" should be given specialized 
priefings as their duties and responsibilities would not, for 
example, require detailed knowledge of "in-status" transfer 
procedures or how to wrap material for ARFCOS delivery. A . 
sample outline on this type of APEA priefing is included. Sim- 
jlarly, a "Mini" Briefing is provided for those persons who re- 
quire extremely Limited knowledge about APEX. Both are examples 
of the type of “tailored” prieEings that should be developed 
py briefers for types of persons routinely priefed into APEX. 
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APEX BRIEFING GUIDE QUTLINE 


Introduction (presented at unclassified level): 


General explanation of extreme sensitivity of the category of 
APEX information for which the person is being given access. 


Advisory that the person will be required to sign a contractual 
"Nondisclosure Agreement" (NDA) as a condition of access to APEX 
material. (Allow the person to read the NDA if applicable/asked. ) 


Highlight the NDA requirements for prepublication review and 
cover other matters as detailed in the legal instructional 
package on the NDA. 


Allow the individual to express any reservations which he/she 
may have concerning the NDA or access to APEX materials. (Such 

servations could, in some cases, result in terminating the 
briefing at this point until issues are resolved.) 


Substantive Briefing (classified according to content): 


Discuss need for, purpose of, and structure of the APEX Special 
Access Control System. (Use APEX Security Manual as source.) 


--~- Discuss the APEX "chain of command" (e. g., President, DCI, 
APEX Steering Group/APEX Control Staff, Intelligence Com- 
munity SIOs, appropriate APEX Security Officer(s) and APEX 
Control Officer(s), etc, as required). 


Provide explanation of the specific level of APEX access for 
which the person will oe authorized access (e. g., operational 
compartment, subdcompartment, product, APEX General Phase I/II). 


~-~ Cover its relationship to other information information 
processed py the US Government. 


--- Provide specific details of the APEX category(ies), as 
appropriate to the person's duty assignment and as pro- 
vided by the appropriate APEX Program Manager. 


Show examples of the APEX material for which the person will be 
authorized and which fall within his/her need~to~know (adjust if 
APEX General Phase I access is involved). Ensure that differences 
petween the various APEX categories are known and recognized. 


Explain the sensitivity of each APEX category for which the 
person will have access. 


-~-~ Discuss the adverse effects on national security that could 
result from unauthorized disclosure of APEX information. 
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Provide APEX administrative security requirements: 
~-- Access verification and certification. 
--- Pre-publication review responsibilities and procedures, 


--- SBI update requirement and personnel security reporting 
responsibilities and procedures. 


~-- Review classification guides pertinent to the APEX ma~ 
terial to which the person will have access. (OPTIONNI,) 


--~ Provide guidance on "portion marking" APEX material. 
--~ Meaning/purpose of colored APEX coversheets. 


~-- Inventory, certificate of destruction, and receipting 
procedures. 


--- "Two-person" rule. 
~-- Discuss individual responsibilities: 
~ No discussion of APEX information over non-secure 
telephones or in areas that are not accredited as 
an APEX Control Facility (ACF). Advise location of 


secure phones and ACFs. 


~ Discuss administrative reporting requirements and -pro- 
cedures: 


oo Unofficial foreign travel (DCID 1/20) 
oo Security violations and incidents 
oo Contacts with foreign nationals 


oo Attempts by unauthorized persons to obtain APEX 
information 


00 Possible loss or compromise of APEX material 
oo Personnel security concerns (ie @., excessive 
drinking; illegal use of drugs; sudden, unexplained, 


affluence, etc) 


~-- Discuss requirements and procedures for couriering APEX 
materials 


Discuss physical security requirements and procedures: 
--- "Define" an APEX Control Facility (ACF). 
--- Discuss levels of access held by ACFs and how to verify 


such levels. Cover how to establish or expand an ACF 
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-~-~ Discuss general APEX physical security storage require- 
ments and the specific storage and handling requirements 
of the APEX material the person will have access. 


--- Advise on how and where to report physical insecurities 
relating to APEX storage OF handling. 


Local procedures for APEX-indoctrinated visitors. 
"“In-status" transfer procedures. (OPTIONAL) 
The need for, and frequency of, APEX reindoctrinations. 


Responsibility and procedures for, and applicability of, 
debriefs from APEX access. 


Individual classification management responsibilities: 


--~- General provisions of Fxecutive Order 12065 and depart- 
mental or agency implementers. 


-~- General provisions of Information Security Oversight 
Office (ISSO) Directive Number One. 


--- Discussion of specific classification/compartmentation 
guides associated with the APEX material to which the 
person will have access. (Use Program Manager and other 
classification guides as source.) 


m~-- Classification challenges (rights and procedures). 

--~ Specific decompartmentation and/or sanitization guide- 
lines associated with the APEX material to which the 
person will have access. (Use Program Manager and other 
guidelines as source.) 

--- Classification assignment responsibilities. 


Pre-existing Sensitive Compartmented Information (SCI): 


----Identify pre-existing SCI equating to the APEX material 
to which the person will have access. 


--- Advise general handling and storage procedures and 
restrictions for such material. 


~~- Relationship of the material to APEX (e. ge, sanitize or 
decompartment if possible; if not, then “recontrol" as 
APEX using applicable classification/decompartmentation 
guides and threshold criteria). 
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--~ Direct any questions to the appropriate APEX Security 
or Control Officer, or alternates. 


Techniques used py foreign intelligence organizations to 
obtain classified information. 


--- Reporting of attempts to obtain classified information. 


Conclusion Briefing (presented at unclassified level): 


Penalties for espionage and unauthorized disclosure. 


Sanctions for violation or disregard of APEX security procedures. 


Persons/offices to contact whenever there is a question or con- 
cern regarding APEX security or procedures, 


Signing of the APEX Nondisclosure Agreement (NDA). 


- Explanation of legal obligations (Use legal instructional 


packet as source). 
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APEX "MINI" BRIEFING 


(Combining the needs to introduce people into APEX with the 

need to limit information to the essential level (i. e., persons 
to be given APEX General Phase I access and certain persons 

in industry), the following "Mini" Briefing can be used at 

the discretion of briefers who believe it will satisfy their 
requirements. ) 


-~ The US Government, in the interest of tightenting security, 
has requested that all access approvals on Special Projects 
be reviewed. It has also instituted new security procedures 
and new forms which will make security accountability a great 
deal easier. 


~~ The only immediate concern to you is the signing of the new 
form. Your security concerns remain the same; there is no 
change in your status on the job. Keep on with what you are 
doing, report any security concerns to your Security Officer 
(by name) and continue to protect the information you have 
been given. 
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(General Officers and other "VIPs" should be given specialized 
briefings as their duties and responsibilities would not, for 
example, require detailed knowledge of "in-status" transfer pro- 
cedures or how to wrap material for ARFCOS delivery. The following 
is an outline of this type of APEX briefing.) 


Introduction (presented at unclassified level): 


~~ General explanation of extreme sensitivity of the category of 
APEX information for which the person is being given access. 


~~ Advisory that the person will be required to sign a contractual 
"Nondisclosure Agreement" (NDA) as a condition of access to APEX 
material. (Allow the person to read the NDA if applicable/asked.) 


~~ Highlight the NDA requirements for prepublication review and 
cover other matters as detailed in the legal instructional 
package on the NDA. 


-~ Allow the individual to express any reservations which he/she 
may have concerning the NDA or access to APEX materials. (Such 
reservations could, in some cases, result in terminating the 
briefing at this point until issues are resolved.) 

Substantive Briefing (classified according to_ content): 

~~ Appreviated discussion of the need for, purpose of, and structure 


of the APEX Special Access Control System. (Use APEX Security 
Manual as source.) 


-~- Highlights of key aspects of the specific level of APEX access for 
which the person will be authorized access (e. g., operational 
compartment, subcompartment, product, or other). (Use Program 
Manager manuals as source.) 


-~ Office/person to contact for access verification and certifica- 
tion. 


-- Individual responsibilities: 

--~ No discussions of APEX information over non-secure telephones 
or in areas that are not accredited as an APEX Control 
Facility (ACF). Advise location of secure phones and ACFs. 

--~ Administrative reporting requirements and procedures: 
~ Unofficial foreign travel (DCID 1/20) 
~ Security violations and incidents 


-~ Contacts with foreign nationals 


- Attempts by unauthorized persons to obtain APEX informa- 
tion 


~ Possible loss or compromise of APEX material 
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~ Personnel security concerns (Cc 
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Pre-pupdlication review requirements and procedures. 
Requirements and procedures for couriering APEX material. 
General classification, decompartmentation and sanitization 


procedures and guidelines. (Use Program Manager manuals and 
guides as source.) 


- Pre-existing SCI equating to APHEX material to which the person 


will have access. 


Conclusion Briefing (presented at unclassified level): 


Discussion, as required, of the penalties for espionage and 
unauthorized disclosure. 


Discussion, as required, of sanctions for violations or dis- 
regard of APEX security procedures. 


Persons/offices to contact whenever there is a question or 
concern regarding APEX security or procedures. 


Signing of the APEX Nondisclosure Agreement (NDA). 


Explanation of legal obligations. (Use legal instructional 
packet as source.) 
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